Question 71

The SOC has received reports of slowness across all workstation network segments. The currently installed antivirus has not detected anything, but a different anti-malware product was just downloaded and has revealed a worm is spreading Which of the following should be the NEXT step in this incident response?
  • Question 72

    A security analyst was alerted to a tile integrity monitoring event based on a change to the vhost-paymonts .conf file The output of the diff command against the known-good backup reads as follows

    Which of the following MOST likely occurred?
  • Question 73

    An analyst is performing penetration testing and vulnerability assessment activities against a new vehicle automation platform.
    Which of the following is MOST likely an attack vector that is being utilized as part of the testing and assessment?
  • Question 74

    A security analyst needs to assess the web server versions on a list of hosts to determine which are running a vulnerable version of the software and output that list into an XML file named webserverlist.xml. The host list is provided in a file named webserverlist.txt. Which of the following Nmap commands would BEST accomplish this goal?
  • Question 75

    A security analyst notices the following entry while reviewing the server togs OR 1=1' ADD USER attacker' PW 1337password' ---- Which of the following events occurred?